outlook add in compromises accounts

Malicious Outlook Add-in Snares 4,000 Microsoft Accounts in Store’s Security Blindspot

A malicious Outlook add-in dubbed AgreeToSteal harvested over 4,000 Microsoft credentials by exploiting a glaring oversight in the company’s app store vetting process. The attack leveraged an expired Vercel subdomain to transform a legitimate calendar tool into a phishing operation—all without triggering security reviews since Microsoft only scrutinizes manifest files during initial submission, not ongoing content changes. Victims encountered fake login pages requesting everything from passwords to credit card details, with data funneled through Telegram’s Bot API as the phishing infrastructure remained operational even after store removal, revealing deeper vulnerabilities in marketplace security architecture.

A seemingly harmless calendar tool hiding in plain sight on Microsoft’s official app store has become the first documented case of a malicious Outlook add-in stealing credentials in the wild. The compromised AgreeTo add-in, dubbed AgreeToSteal by Koi Security researchers, harvested over 4,000 Microsoft account credentials through a supply chain attack that exploited a critical oversight in how the tech giant vets its marketplace offerings.

The attack vector was elegantly simple. AgreeTo, originally marketed as a calendar connection tool, enjoyed a respectable 4.71-star rating before its developer abandoned it in December 2022. The add-in remained listed in Microsoft’s store even after its Chrome extension counterpart was removed in February 2025.

Meanwhile, attackers quietly claimed the expired Vercel subdomain where the add-in loaded its resources, swapping legitimate content for a convincing phishing operation without triggering a single security review.

Here’s where Microsoft’s vetting process reveals its Achilles’ heel: the company only examines an add-in’s manifest file during initial submission. Once approved, add-ins pointing to live URLs can serve whatever content their operators choose through iframes embedded directly inside Outlook. No resubmission required. No fresh review triggered. The original manifest‘s ReadWriteItem permissions—granting access to read and modify emails—remained fully intact for the attackers to exploit.

Victims encountered a fake Microsoft login page in their Outlook sidebar, prompting them to “sign in to continue.” The phishing kit captured far more than usernames and passwords. Credit card numbers with CVVs, banking security question answers for Interac e-Transfer interception, and IP addresses all flowed to the attackers via Telegram’s Bot API.

After harvesting credentials, the operation redirected victims to genuine Microsoft login pages, maintaining the illusion that nothing unusual had occurred.

Koi Security discovered the breach after infiltrating the attacker’s Telegram channel, where credentials were being tested in real-time. The researchers recovered evidence of 12 additional phishing kits operating under the same umbrella, suggesting AgreeToSteal represented just one component of a sprawling multi-brand operation targeting Microsoft users particularly. Microsoft has since recommended implementing runtime URL checks to validate add-in resources continuously and prevent similar domain hijacking attacks. The platform’s lack of periodic content monitoring creates an environment where approved add-ins can morph into malicious tools without oversight.

Microsoft has since removed the malicious add-in from its store, though the associated phishing sites continued operating afterward. Koi Security reached out to victims directly, but the incident exposes a vulnerability eerily reminiscent of browser extension supply chain attacks—a threat vector now confirmed for productivity suite add-ins.

The episode raises uncomfortable questions about marketplace security. When vetted applications can transform into credential harvesters without retriggering approval workflows, trust becomes a liability.

For the 4,000-plus victims whose data now circulates in cybercriminal channels, that distinction matters little. What began as a calendar convenience ended as a masterclass in exploiting the gaps between platform oversight and developer autonomy.

Final Thoughts

The recent breach involving a malicious Outlook add-in has revealed significant vulnerabilities in Microsoft’s app vetting process, catching many enterprise users off guard. With 4,000 Microsoft accounts compromised, IT admins must now approach add-ins with caution, treating them as uninvited guests that require thorough credential verification before access is granted.

The Computer Techs Team is here to assist your organization in navigating these security challenges. We can help implement robust security measures and ensure your systems are protected against similar threats. Don’t wait for a breach to happen—take proactive steps today.

For expert guidance and support, click on our contact us page to get in touch with our team.

Similar Posts